These services encrypt and decrypt messages to ensure Personal Health Information is not susceptible to eavesdropping or tampering while in transit across networks. Encryption services will be based on industry best practices including consideration for use of IPSEC, X509 V3 digital certificates, and a common set of baseline cryptographic algorithms and key lengths.
(See EHRi Privacy and Security Conceptual Architecture 7.9 Encryption Service in the Desired Future State)
General Info | |
---|---|
Name | Encrypt/ Decrypt Services |
Visibility | public |
Active | false |
Abstract | false |
Leaf | false |
Root | false |
Owner | Classes |
Operations | |
---|---|
Name | Return Type |
![]() |
Relations | |||
---|---|---|---|
Name | Type | Begins | Ends |
![]() | generalization | Encrypt/ Decrypt Services | Messaging Services |
Description: This service component provides for the protection of PHI in transit via message-based encryption (i.e., encryption of data in transit across networks and between servers). Such encryption is short-lived (for the duration of transport only).
(See EHRi Privacy and Security Conceptual Architecture section A.7.4 Message Encryption).
Used by:
Uses:
Message encryption services do not directly rely upon other privacy or security service components.
General Info | |
---|---|
Name | Message Encryption |
Owner | Encrypt/ Decrypt Services |
Concurrency | sequential |
Query | false |
Visibility | public |
Scope | instance |
Abstract | false |
Leaf | false |
Root | false |